Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.14% | — | Adguardhome | 15/7/2026 | 30/7/2026 | AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle, weakening DNS response matching for… | |
| Aplazada | Crítica (9.2) | 0.84% | — | Adguard HomeAI | 8/6/2026 | 23/7/2026 | AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path construction within the… | |
| Analizada | Crítica (9.8) | 0.78% | — | Adguardhome | 11/3/2026 | 17/6/2026 | AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is accepted, the resulting HTTP/2 connection is… | |
| Analizada | Media (5.3) | 0.29% | — | Adguard Trusttunnel | 29/1/2026 | 17/6/2026 | TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks 1024 bytes and calls `extract_client_random(...)`. If `parse_tls_plaintext` fails (for example, a fragmented/partial ClientHello split across TCP writes),… | |
| Analizada | Alta (7.1) | 0.26% | — | Adguard Trusttunnel | 29/1/2026 | 17/6/2026 | TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114. In `tcp_forwarder.rs`, SSRF protection for `allow_private_network_connections = false` was only applied in the `TcpDestination::HostName(peer)` path. The… | |
| Analizada | Media (5.5) | 0.14% | — | Adguard FOR Safari | 17/7/2025 | 17/6/2026 | An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be disabled in version 1.11.22. | |
| Aplazada | Media (6.1) | 0.29% | — | AdguardAI | 27/1/2025 | 17/6/2026 | Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix component. | |
| Aplazada | Media (4.9) | 0.80% | — | Adguard HomeAI | 8/10/2024 | 17/6/2026 | An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via placing a crafted file into a readable directory. | |
| Aplazada | Alta (8.8) | 0.21% | — | AdguardhomeAI | 13/6/2024 | 17/6/2026 | An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary. | |
| Analizada | Alta (7.5) | 0.81% | — | Adguard DNS | 25/8/2023 | 17/6/2026 | AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets. | |
| Modificada | Alta (7.8) | 0.61% | — | Adguard | 26/1/2023 | 17/6/2026 | Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation. | |
| Modificada | Media (5.4) | 0.30% | — | Adguardhome | 11/10/2022 | 17/6/2026 | In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules. | |
| Modificada | Alta (7.5) | 5.0% | — | Adguard Home | 3/3/2021 | 17/6/2026 | An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their password offline, because the hash of the password is stored in the cookie. |